You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I see an alert pop up on the screen with the document.domain showing that the JS within the url was inserted into the page.
Inspecting the page I can see that the metadata in the head contains opengraph tags for a twitter card, and the twitter:url tag has the offending JS appended after it
I am unsure where the twitter card metadata is coming from, our app does not add it (as far as I can see) but the dash docs only claim to add 3 meta tags by default, none of which is twitter/og related. Is this part of dash?
Another maybe related note, providing an array of meta tags to the Dash command as per the docs does not change the tags that are output.
Expected behavior
No JS alert should be seen. Url should be escaped before insertion into the page.
I am aware this could be specific to our app, but I can find nothing within our code that is modifying these tags, so it appears to be an issue with dash. Any help or guidance would be appreciated.
The text was updated successfully, but these errors were encountered:
Thanks @alexcjohnson, I've updated to 2.14.2 and that has resolved the issue. My apologies, I know I upgraded as part of my attempts to solve the issue, and only raised the issue because it hadn't worked! But clearly I made a mistake somewhere 🤦♂️.
Describe your context
Describe the bug
When accessing this url (or similar)
http://0.0.0.0:8050/wp-content/plugins/dzs-videogallery/deploy/designer/preview.php?swfloc="><script>alert(document.domain)</script>
I see an alert pop up on the screen with the document.domain showing that the JS within the url was inserted into the page.
Inspecting the page I can see that the metadata in the head contains opengraph tags for a twitter card, and the
twitter:url
tag has the offending JS appended after itOur app is using an index string as per the docs, but this issue appears even without it.
I am unsure where the twitter card metadata is coming from, our app does not add it (as far as I can see) but the dash docs only claim to add 3 meta tags by default, none of which is twitter/og related. Is this part of dash?
Another maybe related note, providing an array of meta tags to the
Dash
command as per the docs does not change the tags that are output.Expected behavior
No JS alert should be seen. Url should be escaped before insertion into the page.
I am aware this could be specific to our app, but I can find nothing within our code that is modifying these tags, so it appears to be an issue with dash. Any help or guidance would be appreciated.
The text was updated successfully, but these errors were encountered: